Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SonicWall Zero-Days Exploited Before Patch Release

SonicWall Zero-Days Exploited Before Patch Release

Posted on July 20, 2026 By CWS

Recently, cybersecurity firm Volexity revealed that two zero-day vulnerabilities in SonicWall appliances were actively exploited by malicious actors weeks before security patches were made available. These vulnerabilities, identified as CVE-2026-15409 and CVE-2026-15410, were officially acknowledged by SonicWall in a public advisory released on July 14. The advisory alerted users to the risks associated with the flaws, which allowed remote attackers to compromise SMA1000 secure remote access devices.

SonicWall’s Response and Vulnerability Patch

SonicWall responded promptly by issuing hotfix updates to mitigate the security risks posed by the vulnerabilities. The company worked closely with Volexity during the investigation of these incidents. According to Volexity, the exploitation of these zero-days was attributed to a threat group they track as UTA0533, with evidence suggesting that the attacks began as early as June 22.

While the specific motives of the threat actors remain ambiguous, Volexity’s analysis suggests that their actions align more closely with state-sponsored advanced persistent threat (APT) activities rather than financially motivated cybercrime.

Technical Details of the Attack

Upon gaining access to the SonicWall appliances, the attackers deployed a custom malware named KnuckleBall. This malware facilitated the injection of additional tools into legitimate processes, including a specialized Java webshell called OrangeTail and an open-source proxy named Suo5. With root access, the attackers could potentially capture network traffic and access cached credentials.

Despite the significant capabilities demonstrated by UTA0533 in compromising the SonicWall devices, Volexity noted that the threat group struggled to move laterally within networks or access other systems.

Implications and Future Outlook

In response to these events, the Cybersecurity and Infrastructure Security Agency (CISA) has included the identified vulnerabilities in its Known Exploited Vulnerabilities (KEV) catalog, which now features 17 flaws affecting SonicWall products. This underscores the critical need for organizations to remain vigilant and ensure timely application of security patches to protect against emerging threats.

The ongoing investigation and the release of technical details by Volexity highlight the importance of collaboration between cybersecurity firms and vendors in identifying and mitigating advanced threats. As the landscape of cyber threats continues to evolve, maintaining robust security measures and staying informed about potential vulnerabilities is crucial for safeguarding sensitive information.

Security Week News Tags:APT, CVE-2026-15409, CVE-2026-15410, Cybersecurity, KnuckleBall, Malware, SMA1000, SonicWall, Volexity, zero-day vulnerabilities

Post navigation

Previous Post: HollowGraph Malware Exploits Microsoft 365 Calendars
Next Post: AI Discovers WordPress Flaw, Potentially Worth $500,000

Related Posts

Highly Popular NPM Packages Poisoned in New Supply Chain Attack Highly Popular NPM Packages Poisoned in New Supply Chain Attack Security Week News
Nevada Confirms Ransomware Attack Behind Statewide Service Disruptions Nevada Confirms Ransomware Attack Behind Statewide Service Disruptions Security Week News
Oracle PeopleSoft Vulnerability Exploited by ShinyHunters Oracle PeopleSoft Vulnerability Exploited by ShinyHunters Security Week News
Shai-Hulud Supply Chain Attacks Target NPM and PyPI Packages Shai-Hulud Supply Chain Attacks Target NPM and PyPI Packages Security Week News
NewCore Launches with  Million in Seed Funding NewCore Launches with $66 Million in Seed Funding Security Week News
Ivanti Patches Two EPMM Zero-Days Exploited to Hack Customers Ivanti Patches Two EPMM Zero-Days Exploited to Hack Customers Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Defender XDR Vulnerability in Network Detection
  • HollowGraph Malware Exploits Microsoft 365 Calendar for C&C
  • SonicWall Flaws Exploited to Deploy Malware
  • Estée Lauder Faces Data Breach from Oracle Zero-Day Attack
  • Meta Awards $78,000 for Major Support Data Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Defender XDR Vulnerability in Network Detection
  • HollowGraph Malware Exploits Microsoft 365 Calendar for C&C
  • SonicWall Flaws Exploited to Deploy Malware
  • Estée Lauder Faces Data Breach from Oracle Zero-Day Attack
  • Meta Awards $78,000 for Major Support Data Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark